BIT-oauth2-proxy-2026-40574

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/oauth2-proxy/BIT-oauth2-proxy-2026-40574.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-oauth2-proxy-2026-40574
Aliases
Published
2026-04-23T08:47:00Z
Modified
2026-09-08T08:48:10Z
Summary
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
Details

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enforcement option. An attacker may be able to authenticate with an email claim such as attacker@evil.com@company.com and satisfy an allowed domain check for company.com, even though the claim is not a valid email address. The issue ONLY affects deployments that rely on email_domain restrictions and accept email claim values from identity providers or claim mappings that do not strictly enforce normal email syntax. This vulnerability is fixed in 7.15.2.

Database specific
{
    "cpes": [
        "cpe:2.3:a:oauth2_proxy_project:oauth2_proxy:*:*:*:*:*:go:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / oauth2-proxy

Package

Name
oauth2-proxy
Purl
pkg:bitnami/oauth2-proxy

Severity

  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.15.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/oauth2-proxy/BIT-oauth2-proxy-2026-40574.json"